MALICIOUS — CRITICAL
bexlorit-ki.com: Confirmed Binance Brand-Impersonation Phishing
bexlorit-ki[.]
Analysis of the domain bexlorit-ki.com confirms its classification as a high-risk phishing site impersonating Binance, a cryptocurrency exchange.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Disponibilité
- Contenu indisponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bexlorit-ki.com — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Binance; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 98/100. Bureau d’enregistrement: Hosting Concepts.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of the domain bexlorit-ki.com confirms its classification as a high-risk phishing site impersonating Binance, a cryptocurrency exchange. The domain was registered on February 21, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, with nameservers assigned to ina1.registrar.eu, ina2.registrar.eu, and ina3.registrar.eu. Infrastructure analysis reveals resolution to IP address 104.21.75.28, hosted on Cloudflare's network (AS13335) in the United States. No SSL certificate was detected, increasing the risk of unencrypted data transmission. The domain is currently offline, returning an HTTP 410 status code, which indicates intentional removal or decommissioning.
Prior to takedown, the page title 'Bexlorit™ - KI-Trading Deutschland 2026' was observed, suggesting a localized German-language phishing campaign targeting users with artificial intelligence-themed trading scams. While the exact content of the site remains unanalyzed, the combination of the page title and the declared brand target (Binance) aligns with known tactics of fraudulent investment schemes. Detection data supports the malicious classification: the domain appears on three security blocklists, is flagged by Google Safe Browsing for social engineering, and holds a Gridinsoft trust score of 0/100. Sixteen of 95 security vendors on VirusTotal flagged the domain as malicious prior to its removal. Protective measures by PhishDestroy, MetaMask, and SEAL further corroborate the phishing assessment.
Defenders should treat this domain as confirmed malicious infrastructure. Although currently offline, historical DNS records and detection timestamps should be preserved for forensic analysis. Organizations are advised to block the domain, its resolved IP, and monitor for re-registration or related domains using similar naming conventions or registrar patterns. No evidence of a phishing kit or additional payloads was provided; further investigation into associated campaigns is recommended.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260125-E3E0DF Recipient: abuse@registrar.eu Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.